CVE-2008-0807

lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.

Published: 2008-02-19 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-0807 is rated Moderate Risk (44.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.68%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-0807

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-06 0.56% 0.68% +0.12%
2 2025-03-30 0.80% 0.56% -0.24%
3 2025-03-29 0.80%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-0807

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.9 2.0 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
6.8 4.9 [email protected]

Weakness enumeration for CVE-2008-0807

OS Trackers for CVE-2008-0807

vendor priority summary link
redhat high https://access.redhat.com/security/cve/CVE-2008-0807
ubuntu low CVE-2008-0807 low priority: Ubuntu including 1 source packages (turba2), 9 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): released 5, ignored 4. https://ubuntu.com/security/CVE-2008-0807

Affected software / configurations for CVE-2008-0807

Vendor Product Version Raw CPE
horde groupware 1.0.3 cpe:2.3:a:horde:groupware:1.0.3:*:*:*:*:*:*:*
horde groupware_webmail_edition 1.0.4 cpe:2.3:a:horde:groupware_webmail_edition:1.0.4:*:*:*:*:*:*:*
horde turba_contact_manager 2.1.6 cpe:2.3:a:horde:turba_contact_manager:2.1.6:*:*:*:*:*:*:*

References for CVE-2008-0807

URL Tags
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058
http://lists.horde.org/archives/announce/2008/000378.html Patch
http://lists.horde.org/archives/announce/2008/000379.html Patch
http://lists.horde.org/archives/announce/2008/000380.html Patch
http://lists.horde.org/archives/announce/2008/000381.html Patch
http://secunia.com/advisories/28982 Vendor Advisory
http://secunia.com/advisories/29071
http://secunia.com/advisories/29184
http://secunia.com/advisories/29185
http://secunia.com/advisories/29186
http://www.debian.org/security/2008/dsa-1507
http://www.securityfocus.com/bid/27844 Patch
http://www.securitytracker.com/id?1019433
http://www.vupen.com/english/advisories/2008/0593/references
https://bugzilla.redhat.com/show_bug.cgi?id=432027
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html
cvelogic Threat Intelligence